Information processing device, terminal device, information processing method, and recording medium

The information processing system enhances immigration inspection efficiency by evaluating traveler creditworthiness based on historical data to expedite eligible repeat travelers through automated gates.

JP2025169379APending Publication Date: 2025-11-12NEC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025136374
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-11-12

AI Technical Summary

Technical Problem

Existing immigration inspection systems inefficiently handle repeat travelers who are eligible for automated gates, requiring them to undergo the same inspection processes as first-time travelers.

Method used

An information processing system that evaluates a traveler's creditworthiness based on historical travel data to streamline inspection procedures, using a management server to analyze past trips, authentication results, and biometric information to facilitate efficient use of automated gates.

Benefits of technology

Improves the efficiency of inspection procedures by distinguishing between eligible repeat travelers and first-time travelers, allowing for expedited processing through automated systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025169379000001_ABST
    Figure 2025169379000001_ABST
Patent Text Reader

Abstract

To provide an information processing device, terminal device, information processing method and recording medium, which streamline various inspection procedures for overseas travelers.SOLUTION: An information processing device is provided, comprising a determination unit configured to determine information on trustworthiness of a traveler planning a new trip based on history information regarding past trips of the traveler in multiple authentication stages, and an output unit for outputting the information on the trustworthiness.SELECTED DRAWING: Figure 34
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, a terminal device, an information processing method, and a recording medium. [Background technology]

[0002] Patent Document 1 discloses an immigration inspection system in which a KIOSK terminal determines whether a traveler is permitted to use an automated gate. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-222459 Summary of the Invention [Problem to be solved by the invention]

[0004] In the immigration inspection system described in Patent Document 1, travelers who are not eligible to use automated gates must go through the same inspection process as first-time travelers, even if they are, for example, good travelers who have traveled multiple times. As a result, this immigration inspection system has the problem of being unable to efficiently carry out the inspection procedures for travelers.

[0005] In view of the above-mentioned problems, the present invention aims to provide an information processing device, a terminal device, an information processing method, and a recording medium that can improve the efficiency of various inspection procedures for travelers. [Means for solving the problem]

[0006] According to one aspect of the present invention, an information processing device is provided that includes an acquisition unit that acquires information regarding the creditworthiness of a passenger planning a new trip based on historical information regarding the passenger's past trips at multiple authentication stages, and an output unit that creates information regarding the screening of the new trip based on a comparison of the acquired information regarding the passenger's creditworthiness with information regarding screening criteria, and outputs the information regarding the screening.

[0007] According to yet another aspect of the present invention, there is provided an information processing method comprising the steps of: acquiring information regarding the creditworthiness of a passenger planning a new trip based on historical information regarding the passenger's past trips at multiple authentication stages; and creating information regarding the screening of the new trip based on a comparison of the acquired information regarding the passenger's creditworthiness with information regarding screening criteria, and outputting the information regarding the screening.

[0008] According to yet another aspect of the present invention, a program is provided for causing a computer to execute the steps of acquiring information about a passenger's creditworthiness based on historical information about the passenger's past travels at multiple authentication stages when the passenger is planning a new trip, and creating information about the screening for the new trip based on a comparison of the acquired information about the passenger's creditworthiness with information about screening criteria, and outputting the information about the screening. [Effects of the Invention]

[0009] According to the present invention, an information processing device, a terminal device, an information processing method, and a recording medium are provided that can improve the efficiency of various inspection procedures for travelers. [Brief explanation of the drawings]

[0010] [Figure 1] 1 is a schematic diagram showing an example of the overall configuration of a passenger control system in a first embodiment. [Figure 2A] FIG. 3 is a diagram illustrating an example of information stored in a user information DB according to the first embodiment. [Figure 2B]FIG. 3 is a diagram showing an example of information stored in a travel / authentication history information DB in the first embodiment. [Figure 2C] FIG. 3 is a diagram illustrating an example of information stored in a credibility information DB in the first embodiment. [Figure 3] FIG. 2 is a block diagram illustrating an example of a hardware configuration of a management server according to the first embodiment. [Figure 4] 2 is a block diagram showing an example of a hardware configuration of a check-in terminal in the first embodiment. FIG. [Figure 5] 2 is a block diagram showing an example of a hardware configuration of a business terminal according to the first embodiment. FIG. [Figure 6] 1 is a block diagram showing an example of a hardware configuration of a security inspection device according to a first embodiment. [Figure 7] 1 is a block diagram showing an example of a hardware configuration of an automated gate apparatus according to a first embodiment. [Figure 8] 2 is a block diagram showing an example of a hardware configuration of a boarding gate apparatus according to the first embodiment. FIG. [Figure 9] 3 is a block diagram showing an example of a hardware configuration of an entrance gate terminal in the first embodiment. FIG. [Figure 10] FIG. 2 is a block diagram showing an example of a hardware configuration of an exit gate terminal in the first embodiment. [Figure 11] 10 is a flowchart illustrating an example of processing by a management server in the first embodiment. [Figure 12] FIG. 4 is a sequence diagram showing an example of processing by a check-in terminal and a management server in the first embodiment. [Figure 13] FIG. 4 is a diagram showing an example of a screen displayed by a check-in terminal in the first embodiment. [Figure 14] FIG. 4 is a sequence diagram showing an example of processing by a safety inspection device and a management server in the first embodiment. [Figure 15] FIG. 3 is a sequence diagram showing an example of processing by the automated gate device and the management server in the first embodiment. [Figure 16]FIG. 4 is a sequence diagram showing an example of processing by a boarding gate device and a management server in the first embodiment. [Figure 17] FIG. 3 is a sequence diagram showing an example of processing by the automated gate device and the management server in the first embodiment. [Figure 18] FIG. 3 is a sequence diagram showing an example of processing by the automatic customs gate device and the management server in the first embodiment. [Figure 19] FIG. 4 is a sequence diagram showing an example of processing by a business terminal and a management server in the first embodiment. [Figure 20] FIG. 4 is a diagram illustrating an example of a screen displayed on a business terminal in the first embodiment. [Figure 21] FIG. 4 is a diagram illustrating an example of a screen displayed on a business terminal in the first embodiment. [Figure 22] FIG. 4 is a diagram illustrating an example of a screen displayed on a business terminal in the first embodiment. [Figure 23] 10 is a flowchart illustrating an example of processing by a management server in the second embodiment. [Figure 24] FIG. 10 is a schematic diagram illustrating a learning processing method in the second embodiment. [Figure 25] 10 is a flowchart illustrating an example of processing by a management server in the second embodiment. [Figure 26] FIG. 10 is a schematic diagram showing an example of the overall configuration of a passenger control system according to a third embodiment. [Figure 27] FIG. 11 is a block diagram showing an example of the hardware configuration of a user terminal in the third embodiment. [Figure 28] FIG. 11 is a sequence diagram showing an example of processing by the management server and the user terminal in the third embodiment. [Figure 29] FIG. 11 is a diagram showing an example of a screen displayed by a user terminal in the third embodiment. [Figure 30] FIG. 13 is a diagram illustrating an example of the arrangement of signage terminals in the fourth embodiment. [Figure 31] FIG. 13 is a block diagram showing an example of a hardware configuration of a signage terminal according to a fourth embodiment. [Figure 32]FIG. 13 is a sequence diagram illustrating an example of processing by a signage terminal and a management server according to a fourth embodiment. [Figure 33] FIG. 13 is a diagram showing an example of a screen displayed by a signage terminal in the fourth embodiment. [Figure 34] FIG. 11 is a block diagram showing functions of an information processing device according to a fifth embodiment. [Figure 35] FIG. 13 is a block diagram showing functions of a terminal device according to a sixth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, exemplary embodiments of the present invention will be described with reference to the drawings. In the drawings, similar or corresponding elements are designated by the same reference numerals, and descriptions thereof may be omitted or simplified.

[0012] [First embodiment] 1 is a schematic diagram showing an example of the overall configuration of a passenger control system 1 according to this embodiment. The passenger control system 1 according to this embodiment is an information processing system that supports a series of examinations carried out in a first country and a second country for a user (traveling passenger) U who plans to depart a first country by airplane from an airport DA in the first country and enter a second country from an airport AA in a second country different from the first country. The passenger control system 1 is operated, for example, by a public institution such as an immigration authority or a contractor entrusted with the work by such an institution.

[0013] In the passenger control system 1 of this embodiment, a check-in terminal 20, a security inspection device 30, an automated gate device 40, a boarding gate device 50, an automated gate device 60, an automated customs gate device 70, and business terminals 22, 32, 42, 52, 62, and 80 are each connected to a common management server 10 via a network NW. The network NW is configured by a LAN (Local Area Network) including an airport's on-site communication network, a WAN (Wide Area Network), a mobile communication network, etc. The connection method is not limited to a wired method, and may be a wireless method. For ease of explanation, FIG. 1 illustrates only the devices used up to departure at airport DA in the departure country (first country), and only the devices used up to entry at airport AA in the arrival country (second country).

[0014] The management server 10 is an information processing device that manages various inspections when a user U enters or leaves the country. The management server 10 is installed, for example, in the facilities of an airport company that operates an airport DA or an airport AA, an airline, or the like. The management server 10 does not have to be a single server, but may be configured as a server group including multiple servers. For example, a server that performs some of the functions of the management server 10 may be installed in a first country, and another server that performs the remaining functions of the management server 10 may be installed in a second country.

[0015] As shown in Figure 1, the inspection at airport DA in the first country is carried out sequentially in four authentication stages ST1 to ST4 indicated by dashed lines. The inspection at airport AA in the second country is carried out sequentially in two authentication stages ST5 and ST6 indicated by dashed lines. The relationship between each device and the authentication stages will be explained below.

[0016] The check-in terminal 20 is a self-service terminal that allows the user U to carry out the check-in procedure themselves. The check-in terminal 20 is installed in the check-in lobby of the airport. The business terminal 22 is installed at a manned counter in the check-in lobby. Staff S1 uses the business terminal 22 to carry out the check-in procedure for the user U. The check-in procedure is a procedure for registering information to identify at least the user U who is scheduled to board the aircraft. Specifically, it is a procedure for inputting user information including the user U's personal identification information and boarding information. Hereinafter, the check-in procedure carried out in the check-in lobby will be referred to as the "authentication stage ST1." After the user U is authenticated in the authentication stage ST1, he or she moves to the security checkpoint.

[0017] The security inspection device 30 is installed at the security checkpoint in the airport and uses a metal detector to check whether or not the user U is carrying any potentially dangerous metal objects. Note that the security inspection device 30 includes not only metal detectors but also X-ray inspection equipment that uses X-rays to check for the presence of dangerous objects in carry-on baggage, etc. After completing the check-in procedure, the user U undergoes security inspection procedures using the security inspection device 30 at the security checkpoint. The business terminal 32 is installed at a manned counter at the security checkpoint. Staff S2 uses the business terminal 32 to carry out the security inspection procedures for the user U. Hereinafter, the security inspection procedures carried out at the security checkpoint will be referred to as the "authentication stage ST2." After being authenticated at the authentication stage ST2, the user U moves to the departure inspection area.

[0018] The automated gate device 40 is installed at the immigration area in the airport and is a device that automatically performs immigration procedures for a user U. The users U who can use the immigration procedures using the automated gate device 40 may be limited to those who have pre-registered to use the automated gate device 40. The business terminal 42 is installed at a manned counter at the immigration area. An officer S3 uses the business terminal 42 to perform immigration procedures for the user U. Hereinafter, the immigration procedures carried out at the immigration area will be referred to as the "authentication stage ST3." Once the user U is authenticated at the authentication stage ST3, he or she moves to the departure area.

[0019] The boarding gate device 50 is a traffic control device installed at each boarding gate. The boarding gate device 50 verifies that the user U is a passenger on an aircraft that can board through the boarding gate. The business terminal 52 is installed at a manned counter at the boarding gate. An attendant S4 uses the business terminal 52 to process the boarding procedures for the user U onto the aircraft. Hereinafter, the boarding procedures carried out at the boarding gate will be referred to as the "authentication stage ST4." Once the user U is authenticated in the authentication stage ST4, he or she boards the aircraft and departs the first country.

[0020] The automated gate device 60 is installed at the immigration inspection area in the airport and is a device that automatically performs immigration inspection procedures for a user U. The users U who can use the automated gate device 60 may be limited to those who have pre-registered to use the automated gate device 60. The business terminal 62 is installed at a manned counter at the immigration inspection area. An officer S5 uses the business terminal 62 to perform immigration inspection procedures for the user U. Hereinafter, the immigration inspection procedures carried out at the immigration inspection area will be referred to as the "authentication stage ST5." After the user U is authenticated at the authentication stage ST5, he or she moves to the customs inspection area.

[0021] The automated customs gate device 70 is installed at a customs inspection area within an airport and is a device that automatically carries out customs inspection procedures for a user U. The automated customs gate device 70 has an entrance gate terminal 71 and an exit gate terminal 72. The user U may be able to use the automated customs gate device 70 if he or she has pre-registered for use of the automated customs gate device 70. In addition, the business terminal 80 is installed at a manned counter at the customs inspection area. An officer S6 uses the business terminal 80 to carry out customs inspection procedures for the user U. Hereinafter, the customs inspection procedures carried out at the customs inspection area will be referred to as the "authentication stage ST6." Once the user U is authenticated at the authentication stage ST6, he or she can leave the customs inspection area and enter a second country.

[0022] The business terminals 22, 32, 42, 52, 62, and 80 are terminals used by airline and airport facility staff S1 to S6 for their work. For example, they are stationary information processing terminals installed at work locations such as counters where staff work. Note that each business terminal may also be a portable information processing terminal such as a tablet terminal, smartphone, or mobile phone.

[0023] 1, the management server 10 has a user information DB11, a travel and authentication history information DB12, and a creditworthiness information DB13. Note that each database does not need to be a single database, but may be configured as a group of multiple databases using, for example, blockchain technology. Note that the information stored in the user information DB11, the travel and authentication history information DB12, and the creditworthiness information DB13 is assumed to be shared between the first country and the second country.

[0024] 2A is a diagram showing an example of information stored in the user information DB 11. In the user information DB 11, user information regarding each user U is registered for each user ID, which is an identifier that identifies the user U. In this embodiment, the user ID is unique identification information that is different from a passport number.

[0025] The user information registered in the user information DB11 includes mutually associated personal identification information such as the name and nationality of the user U, biometric information, and boarding information such as the flight number of the aircraft the user U is boarding, the departure point, destination, departure time, and boarding gate. In this embodiment, the term "biometric information" refers to a facial image and features extracted from the facial image, but the biometric information is not limited to a facial image and facial features. In other words, biometric authentication may be performed using a fingerprint image, palm print image, ear image, iris image, etc. as the biometric information of the user U.

[0026] 2B is a diagram showing an example of information stored in the travel and authentication history information DB 12. The travel and authentication history information DB 12 includes, for each user ID, personal attribute information, travel history information, and authentication history information for each user U.

[0027] Travel history information is information about a user U who has travel history. For example, travel history information may be registered by the regulatory authorities or airlines of each country when user U enters or departs from that country. Travel history information includes data items such as user U's departure point (point of departure), departure date (departure date), flight number, entry point (arrival point), and entry date (arrival date). The entry point and departure point may refer to the airport of entry and the airport of departure, respectively.

[0028] The authentication history information is information about the authentication results of multiple authentication stages that user U underwent when traveling. In this embodiment, a series of multiple authentication stages is collectively referred to as "inspection." The authentication history information may be registered, for example, by the authorities or airlines of each country when user U enters and departs from that country.

[0029] In this embodiment, the authentication result at each authentication stage is defined as one of three levels: "OK", "-", and "WR". The authentication result "OK" indicates that authentication was successful. The authentication result "-" indicates that authentication has not yet been performed. For example, if user U is a first-time traveler, the authentication result will remain at the value "-" until the user undergoes inspection. The authentication result "WR" indicates that user U has received a "warning" from an official at the authentication stage. Note that if authentication fails at an authentication stage, entry or exit will not be permitted, so another value may be set.

[0030] Specific examples of cases in which a "warning" is given by an officer include (A) when an item that violates carry-on regulations is discovered and confiscated in authentication stage ST2 (security inspection procedure), and (B) when an undeclared item is discovered and a corrected declaration is made in authentication stage ST6 (customs inspection procedure). Note that these are merely examples, and various cases are possible at each authentication stage. Furthermore, in this embodiment, the information of user U who has received a "warning" from an officer is distinguished from the information of individuals on a blacklist whose entry and exit into the country is restricted.

[0031] FIG. 2C is a diagram showing an example of information stored in the creditworthiness information DB13. Here, the creditworthiness information DB13 has user ID and creditworthiness as data items. Creditworthiness is information indicating the level of creditworthiness of user U, evaluated based on travel history information, authentication history information, and personal attribute information from user U's past travel (hereinafter referred to as "first travel"). In other words, creditworthiness is a value representing the degree to which user U is authenticated at each authentication stage. Specifically, in the case of user U who has not had any deficiencies identified in screening during past travels, i.e., in the case of a good traveler, the creditworthiness of user U will be higher than that of a first-time traveler.

[0032] Conversely, if user U was found to have deficiencies in an inspection during a previous trip, the user U's credibility will be lower than that of good travelers and first-time travelers. The authentication result "OK" in Figure 2B is converted to an authentication score of "1." The authentication result "WR" is converted to an authentication score of "-1." And the authentication result "-" is converted to an authentication score of "0." The authentication results are converted for each trip and averaged for each authentication stage for multiple trips. This results in the credibility information shown in Figure 2C. Note that Figure 2C shows that the credibility is calculated not only as an average value for each authentication stage, but also as an average value for all stages.

[0033] Next, an example of the hardware configuration of each device constituting the passenger control system 1 will be described with reference to Figures 3 to 10. Note that devices with the same name but different reference numerals in Figures 3 to 10 have equivalent functions, and therefore detailed descriptions thereof will be omitted in the subsequent drawings.

[0034] 3 is a block diagram showing an example of the hardware configuration of the management server 10. As shown in the figure, the management server 10 has a CPU (Central Processing Unit) 101, a RAM (Random Access Memory) 102, a storage device 103, and a communication I / F 104. Each device is connected to a bus line 105.

[0035] The CPU 101 is a processor that performs predetermined operations in accordance with programs stored in the storage device 103 and has the function of controlling each part of the management server 10. In the management server 10, the CPU 101 functions as a determination part and an output part. The RAM 102 is made up of a volatile storage medium and provides a temporary memory area necessary for the operation of the CPU 101.

[0036] The storage device 103 is configured with a storage medium such as a nonvolatile memory, a hard disk drive, etc., and functions as a storage unit. The storage device 103 stores programs executed by the CPU 101, data referenced by the CPU 101 when the programs are executed, etc.

[0037] The communication I / F 104 is a communication interface based on standards such as Ethernet (registered trademark), Wi-Fi (registered trademark), and 4G, and is a module for communicating with the check-in terminal 20 and the like.

[0038] 4 is a block diagram showing an example of the hardware configuration of check-in terminal 20. As shown in the figure, check-in terminal 20 has a CPU 201, a RAM 202, a storage device 203, a communication I / F 204, an input device 206, a display device 207, and a medium reading device 208. Each device is connected to a bus line 205.

[0039] The input device 206 is, for example, a pointing device such as a touch panel, a keyboard, etc. In the check-in terminal 20 of this embodiment, the display device 207 and the input device 206 are integrally formed as a touch panel. The display device 207 is a liquid crystal display device, an OLED (Organic Light Emitting Diode) display device, etc., and is used to display moving images, still images, characters, etc.

[0040] The medium reading device 208 is a device that reads the passport or airline ticket medium of the user U to acquire information recorded on the passport or airline ticket. The airline ticket medium is, for example, a paper airline ticket or a mobile terminal that displays an e-ticket copy. The medium reading device 208 is composed of, for example, a code reader, an image scanner, a contactless IC (Integrated Circuit) reader, an OCR (Optical Character Reader) device, etc., and acquires information from various media held over its reading unit.

[0041] 5 is a block diagram showing an example of the hardware configuration of business terminal 22. As shown in the figure, business terminal 22 has CPU 221, RAM 222, storage device 223, communication I / F 224, input device 226, display device 227, and medium reading device 228. Each device is connected to bus line 225. Note that the hardware configuration of business terminals 32, 42, 52, 62, and 80 is the same as that of business terminal 22, but some devices may be omitted or other devices may be added as necessary.

[0042] 6 is a block diagram showing an example of the hardware configuration of the security inspection device 30. As shown in the figure, the security inspection device 30 has a CPU 301, a RAM 302, a storage device 303, a communication I / F 304, an input device 306, a display device 307, a biometric information acquisition device 309, and a metal detection gate 310. Each device is connected to a bus line 305.

[0043] The biometric information acquisition device 309 is a device that acquires a facial image of the user U as biometric information of the user U. The biometric information acquisition device 309 is, for example, a digital camera that captures an image of the face of the user U standing in front of the security inspection device 30, and captures the image of the face of the user U.

[0044] The metal detection gate 310 is a gate-type metal detector that detects metal objects worn by a user U who passes through the metal detection gate 310.

[0045] 7 is a block diagram showing an example of the hardware configuration of automated gate device 40. Automated gate device 40 has a CPU 401, RAM 402, storage device 403, communication I / F 404, input device 406, display device 407, biometric information acquisition device 409, and gate 411. Each device is connected to a bus line 405. Note that automated gate device 60 installed at the immigration inspection area has the same hardware configuration as automated gate device 40.

[0046] When the automated gate device 40 successfully verifies the identity of the user U and the user U passes through immigration, the gate 411, under the control of the CPU 401, transitions from a closed state that blocks the user U's passage while on standby to an open state that allows the user U to pass through. The type of gate 411 is not particularly limited, and may be, for example, a flapper gate in which a flapper provided on one or both sides of the passage opens and closes, or a turnstile gate in which three bars rotate.

[0047] 8 is a block diagram showing an example of the hardware configuration of boarding gate device 50. As shown in the figure, boarding gate device 50 has a CPU 501, a RAM 502, a storage device 503, a communication I / F 504, an input device 506, a display device 507, a biometric information acquisition device 509, and a gate 511. Each device is connected to a bus line 505.

[0048] 9 is a block diagram showing an example of the hardware configuration of the entrance gate terminal 71. The entrance gate terminal 71 has a CPU 711, a RAM 712, a storage device 713, an entrance gate door 716, a passage detection sensor 717, a communication I / F 714, and a guide display 718. Each device is connected to a bus line 715.

[0049] The entrance gate door 716 is an opening and closing door that opens and closes under the control of the CPU 711, and transitions between an open state that allows the user U to pass through and a closed state that blocks the user U. The opening and closing method of the entrance gate door 716 is not particularly limited, but may be, for example, a flapper type, a sliding type, a rotating type, or the like.

[0050] When the passage detection sensor 717 detects the passage of user U, it outputs an output signal indicating the passage of user U. Based on the output signals of the multiple passage detection sensors 717 and the order in which they are output, the CPU 711 can determine whether or not user U has passed through the entrance gate terminal 71 and entered the gate passage. The gate passage is the area between the entrance gate terminal 71 and the exit gate terminal 72.

[0051] The guidance display 718 displays a display indicating whether entry into the gate passage is permitted or not, in accordance with control by the CPU 711. When the entrance gate door 716 is in an open state, the guidance display 718 displays that entry into the gate passage is permitted. Furthermore, when the entrance gate door 716 is in a closed state, the guidance display 718 displays that entry into the gate passage is prohibited. The guidance display 718 can display whether entry into the gate passage is permitted or not by, for example, displaying colors, symbols, characters, etc.

[0052] 10 is a block diagram showing an example of the hardware configuration of the exit gate terminal 72. The exit gate terminal 72 has a CPU 721, a RAM 722, a storage device 723, a display device 726, a first camera 727, a second camera 728, an exit gate door 729, a passage detection sensor 720, a communication I / F 724, and a guide display 730. Each device is connected to a bus line 725.

[0053] First camera 727 is a long-range camera that can capture at least the inside of the gate passageway and can capture images at a longer distance than second camera 728. Second camera 728 is a short-range camera that can capture at least the area in front of exit gate terminal 72. The locations at which first camera 727 and second camera 728 are installed are not particularly limited, and may be any locations that can achieve their respective capture ranges.

[0054] The exit gate door 729 is an opening and closing door that opens and closes under the control of the CPU 721, and transitions between a closed state that blocks the passage of the user U and an open state that allows the user U to pass.

[0055] Next, the operation of each device in the passenger control system 1 in this embodiment will be described with reference to FIGS.

[0056] 11 is a flowchart showing an example of processing by the management server 10. This processing is executed at a predetermined interval or at the start of an examination accompanying the user U's travel.

[0057] First, the management server 10 acquires travel and authentication history data (travel history information, authentication history information, and person attribute information) from the travel and authentication history information DB 12 for each passenger ID (step S101).

[0058] Next, the management server 10 digitizes each of the travel history information, authentication history information, and personal attribute information included in the travel and authentication history data (step S102).

[0059] Next, the management server 10 acquires history feature amounts expressed as vectors from the data obtained by digitizing the travel history information, the authentication history information, and the personal attribute information (step S103).

[0060] Next, the management server 10 calculates the creditworthiness of the user U by inputting the history feature amount into a predetermined relational expression (step S104).

[0061] Then, the management server 10 associates the calculated credit rating with the user ID and registers it in the credit rating information DB 13 (step S105).

[0062] Specific examples of methods for calculating history features include the following three methods (A) to (C). Here, we will explain the case where the record related to user U acquired from the travel and authentication history information DB12 shown in Fig. 2B is in the format of {person attribute information (nationality / gender / age), travel history information (place of departure / place of arrival / flight number / departure date / arrival date), authentication history information (ST1 / ST2 / ST3 / ST4 / ST5 / ST6)}. However, the calculation methods are not limited to these.

[0063] (A) When using only authentication history information As shown in Figure 2B, the authentication history information {ST1 / ST2 / ST3 / ST4 / ST5 / ST6} for user U with passenger ID "20159" is {OK, OK, OK, OK, OK, OK}. If the authentication result is quantified as "1" for "OK", "-1" for "Caution", and "0" for "Unauthenticated", the authentication history information becomes {1 / 1 / 1 / 1 / 1 / 1}. Then, if the authentication history information is vectorized, the vector (1,1,1,1,1,1) is obtained as the history feature.

[0064] Furthermore, if the number of trips is multiple, the average of the authentication scores at each authentication stage can be used as the history feature for the authentication result. For example, if the history feature values ​​(1,1,1,1,1,1) and (1,-1,1,1,1,1,-1) are obtained from the authentication history information for two trips, these can be averaged to obtain the history feature value (1,0,1,1,1,0). Furthermore, instead of using the authentication history information for all past trips, the range can be limited, such as the last five trips or within the last three years, for calculation. The same applies if the number of trips is three or more.

[0065] (B) When using travel history information and authentication history information The travel history information {origin / arrival / flight number / departure date / arrival date} for user U with passenger ID "20159" is {NRT,AAA,AB123,12 / 01 / 2018,13 / 01 / 2018}. Furthermore, the origin and destination are quantified by classifying airports in multiple countries into one of the predetermined categories. For example, a Japanese airport (NRT) is assigned a value of "0.8," an airport with stricter screening standards than Japanese airports is assigned a value of "1," and an airport with more lenient screening standards than Japanese airports is assigned a value of "0.6." For example, if the screening standards at the destination country's airport (AAA) are more lenient than those in Japan, the travel history information {origin / arrival} for the passenger ID is assigned a value of {0.8 / 0.6}. This is combined with the historical features related to the authentication history information obtained in (A) above to obtain the vector (0.8, 0.6, 1, 1, 1, 1, 1, 1).

[0066] (C) When using personal attribute information, travel history information, and authentication history information The personal attribute information {nationality / gender / age} for user U whose passenger ID is "20159" is {JPN,M,20}. For example, let us explain how to calculate the history feature for age from the personal attribute information. Here, ages between 0 and 15 are quantified as "1," ages between 16 and 60 are quantified as "0.7," and ages 61 and over are quantified as "0.9." The personal attribute information for user U whose passenger ID is "20159" is {0.7}. Then, by combining this with the history features for the travel history information and authentication history information calculated in (A) and (B) above, the vector (0.7, 0.8, 0.6, 1, 1, 1, 1, 1, 1) is obtained as the history feature.

[0067] Specific examples of algorithms for calculating the credibility from the history feature amount include the following three algorithms (D) to (F), although usable algorithms are not limited to these.

[0068] (D) Averaging calculation method Let T be the credibility, and let the historical feature amount be (F(1),F(2),...,F(n-1),F(n)) based on data for n (≧2) items. In this case, the credibility T can be calculated, for example, using the following relational expression (1). JPEG2025169379000002.jpg15150

[0069] (E) Calculation method by accumulation The credibility T can be calculated, for example, by the following relational expression (2). JPEG2025169379000003.jpg15150

[0070] (F) Weighted average calculation method If the weights for the items (1) to (n) are W(1) to W(n), respectively, the credibility T can be calculated, for example, by the following formula (3). JPEG2025169379000004.jpg15150

[0071] In this case, the weights W(1) to W(n) can be set arbitrarily. For example, the weights of authentication stages ST2 (security inspection procedure) and ST6 (customs inspection procedure) can be set to values ​​greater than the weight of authentication stage ST1 (check-in procedure).

[0072] 12 is a sequence diagram showing an example of the processing of the check-in terminal 20 and management server 10. This processing is executed every time the user U performs the check-in procedure using the check-in terminal 20. Note that the following description will be given taking as an example the case where a passport is selected on the reservation information search screen.

[0073] First, the check-in terminal 20 determines whether or not the passport of the user U has been held over a reading unit (not shown) of the medium reading device 208 (step S201), and waits until the passport is held over (step S201, NO).

[0074] Next, when the check-in terminal 20 determines that the passport has been held over the reading section of the medium reading device 208 (step S201, YES), it acquires the passport information of the user U from the held passport (step S202). The acquired passport information includes the user U's passport number, information on the country of issue of the passport, etc. At this time, the medium reading device 208 can also acquire the user U's personal identification information from the passport.

[0075] Next, the check-in terminal 20 transmits the acquired passport information to the management server 10 (step S203). When the management server 10 receives the passport information from the check-in terminal 20, it acquires the creditworthiness information of the user U using the passport number included in the passport information as a key (step S204). The creditworthiness information includes the user ID and creditworthiness of the user U. The management server 10 transmits the creditworthiness information of the user U to the check-in terminal 20 (step S205).

[0076] Next, upon receiving the creditworthiness information of user U from management server 10, check-in terminal 20 compares the creditworthiness of user U contained in the creditworthiness information with a predetermined threshold (reference value) (step S206). If check-in terminal 20 determines that user U's creditworthiness is equal to or greater than the predetermined threshold (step S206, YES), processing proceeds to step S207. On the other hand, if check-in terminal 20 determines that user U's creditworthiness is less than the predetermined threshold (step S206, NO), check-in terminal 20 notifies user U of a guidance message (step S212) and terminates processing.

[0077] 13 is a diagram showing an example of a screen displayed by check-in terminal 20. Here, a guidance message ("You are currently unable to use the automatic check-in machine. Please complete the check-in procedure at the check-in counter.") is displayed on the screen.

[0078] Next, the check-in terminal 20 determines whether or not the airline ticket medium of the user U has been held over the reading section of the medium reading device 208 (step S207), and waits until the airline ticket medium is held over (step S207, NO).

[0079] Next, when the check-in terminal 20 determines that the airline ticket medium has been held over the reading section of the medium reading device 208 (step S207, YES), it acquires the boarding information of user U from the airline ticket medium (step S208). At this time, the medium reading device 208 can acquire the boarding information of user U (name, flight number, boarding date, boarding airport, arrival airport, boarding time, arrival time, etc.) from the airline ticket medium.

[0080] The check-in terminal 20 then transmits the user information to the management server 10 (step S209), and also transmits status information indicating that the check-in procedure has been completed and the authentication result to the management server 10 (step S210). Upon receiving the information from the check-in terminal 20, the management server 10 updates the user information DB11 and the travel / authentication history information DB12 (step S211). Specifically, the management server 10 updates the status of the user information DB11 to “Check-in procedure completed: 1” using the user ID as a key, and updates the registered face image with the passport face image. Furthermore, the management server 10 updates the authentication result for authentication stage ST1 of user U in the travel / authentication history information DB12 using the user ID as a key. In this way, by registering the passport face image acquired from the passport during the check-in procedure as a registered face image in the user information DB11, matching processing between the captured face image and the registered face image becomes possible in each subsequent authentication stage. In other words, the user ID associated with the registered face image is identification information that can be commonly used in all authentication stages. Using such a common user ID can improve the efficiency of the screening of user U. In this embodiment, the facial image of the user U is not captured during the check-in procedure, but as with other authentication stages described below, the facial image may be captured at the check-in terminal 20. In this case, a matching process with the passport facial image is executed, and both the passport facial image and the captured image are registered separately in the user information DB 11 on the condition that the matching process is successful.

[0081] [Security inspection procedures] 14 is a sequence diagram showing an example of the processing of the security inspection device 30 and the management server 10. This processing is executed when a user U who has completed the check-in procedure undergoes the security inspection procedure.

[0082] The security inspection device 30 constantly or periodically photographs the area in front of the metal detection gate 310 and determines whether the face of a user U standing in front of the metal detection gate 310 is detected in the photographed image (step S301). The security inspection device 30 waits until the biometric information acquisition device 309 detects the face of the user U in the image (step S301, NO).

[0083] When the security inspection device 30 determines that the face of user U has been detected by the biometric information acquisition device 309 (step S301, YES), it photographs the face of user U and acquires the facial image of user U as a target facial image (step S302).

[0084] Next, the security inspection device 30 transmits the target face image of user U captured by the biometric information acquisition device 309 to the management server 10 via the network NW together with a matching request (step S303). As a result, the security inspection device 30 requests the management server 10 to perform a 1:N matching of the target face image of user U captured by the biometric information acquisition device 309 with multiple registered face images registered in the user information DB 11 of the management server 10.

[0085] When the management server 10 receives the target face image and the matching request from the security inspection device 30, it matches the face image of the user U (step S304). That is, the management server 10 matches the target face image received from the security inspection device 30 with a plurality of registered face images registered in the user information DB 11 in a 1:N ratio.

[0086] If the management server 10 determines that the matching result is a mismatch (step S305, NO), the management server 10 transmits the matching result information to the security inspection device 30 (step S307), and the process proceeds to step S309. On the other hand, if the management server 10 determines that the matching result is a match (step S305, YES), the process proceeds to step S306. In step S306, the management server 10 acquires the user ID from the user information DB 11 based on the matching registered face image, and acquires the creditworthiness information using the user ID as a key from the creditworthiness information DB 13. Then, the management server 10 transmits the acquired user ID and creditworthiness information together with the matching result information to the security inspection device 30 (step S308).

[0087] Next, if the security inspection device 30 determines that the comparison result is a match (step S309, YES), it displays notification information including screening criteria corresponding to the user U's creditworthiness on the display device 307 (step S310), and executes security inspection processing for the user U (step S311). In the security inspection processing, the CPU 301 controls each part of the security inspection device 30. As a result, the security inspection device 30 detects metal objects worn by the user U who passes through the metal detection gate 310. After passing through the metal detection gate 310, the user U heads to the departure inspection area.

[0088] Next, the security inspection device 30 transmits status information indicating that the security inspection procedure for the user U has been completed after the facial image verification and the authentication result to the management server 10 via the network NW (step S312).

[0089] When the management server 10 receives the status information and authentication result from the security inspection device 30, it updates the user information DB11 and the travel / authentication history information DB12 (step S313). Specifically, it updates the status in the user information DB11 to "Security inspection procedure completed: 2" using the user ID as a key. It also updates the authentication result for authentication stage ST2 of user U in the travel / authentication history information DB12 using the user ID as a key.

[0090] On the other hand, if the security inspection device 30 determines that the matching result in the management server 10 is a mismatch (step S309, NO), the security inspection device 30 notifies the user U that identity verification has failed (step S314). For example, the security inspection device 30 displays a notification screen on the display device 307 notifying the user U that identity verification has failed.

[0091] [Departure inspection procedures] 15 is a sequence diagram showing the operations of the automated gate device 40 and the management server 10. This process is executed when a user U who has completed the security inspection procedure undergoes the immigration procedure.

[0092] After completing the security inspection procedure, the user U proceeds to the immigration checkpoint and undergoes immigration procedures at the automated gate device 40. The automated gate device 40 and the management server 10 execute the process shown in FIG. 15 each time each of the multiple users U undergoes immigration procedures.

[0093] The automated gate device 40 constantly or periodically photographs the area in front of the device using the biometric information acquisition device 409, and determines whether the face of the user U is detected in the photographed image (step S401). The automated gate device 40 waits until the face of the user U is detected in the image by the biometric information acquisition device 409 (step S401, NO).

[0094] When the automated gate device 40 determines that the face of user U has been detected by the biometric information acquisition device 409 (step S401, YES), it photographs the face of user U and acquires the facial image of user U as a target biometric authentication image (step S402).

[0095] Next, the automated gate device 40 transmits the target face image of user U captured by the biometric information acquisition device 409 to the management server 10 via the network NW together with a matching request (step S403). As a result, the automated gate device 40 requests the management server 10 to perform a 1:N matching of the target face image of user U captured by the biometric information acquisition device 409 with multiple registered face images registered in the user information DB 11 of the management server 10.

[0096] When the management server 10 receives the target face image and the matching request from the automated gate device 40, it matches the face image of the user U (step S404). That is, the management server 10 matches the target face image received from the automated gate device 40 with a plurality of registered face images registered in the user information DB 11 in a 1:N ratio.

[0097] If the management server 10 determines that the matching result is a mismatch (step S405, NO), the management server 10 transmits the matching result information to the automated gate device 40 (step S407), and the process proceeds to step S409. On the other hand, if the management server 10 determines that the matching result is a match (step S405, YES), the process proceeds to step S406.

[0098] In step S406, the management server 10 acquires the user ID from the user information DB 11 based on the matching registered face image, and acquires the credibility information using the user ID as a key from the credibility information DB 13. Then, the management server 10 transmits the acquired user ID and credibility information together with the matching result information to the automated gate device 40 (step S408).

[0099] Next, if the automated gate device 40 determines that the comparison result is a match (step S409, YES), it determines whether the trustworthiness is equal to or greater than a predetermined threshold (step S410). If the automated gate device 40 determines that the trustworthiness is equal to or greater than the predetermined threshold (step S410, YES), it opens the gate 411 (step S411). On the other hand, if the automated gate device 40 determines that the trustworthiness does not meet the predetermined threshold (step S410, NO), it notifies the user of error information (step S415). For example, a notification screen including a message such as "Please complete immigration procedures at a manned counter" is displayed on the display device 407.

[0100] Next, the automated gate device 40 transmits status information indicating that the immigration procedure for the user U has been completed after the facial image verification and the authentication result to the management server 10 via the network NW (step S412).

[0101] When the management server 10 receives the status information and authentication result from the automated gate device 40, it updates the user information DB11 and the travel / authentication history information DB12 (step S413). Specifically, it updates the status in the user information DB11 to "Immigration inspection procedure completed: 3" using the user ID as a key. It also updates the authentication result for authentication stage ST3 of user U in the travel / authentication history information DB12 using the user ID as a key.

[0102] On the other hand, if the automated gate device 40 determines that the comparison result in the management server 10 is a mismatch (step S409, NO), the automated gate device 40 notifies the user U that identity verification has failed (step S414). For example, the automated gate device 40 displays a notification screen on the display device 407 notifying the user U that identity verification has failed.

[0103] [Aircraft boarding procedures] FIG. 16 is a sequence diagram showing the operation of the boarding gate device 50 and the management server 10. As shown in FIG.

[0104] The boarding gate device 50 constantly or periodically photographs the area in front of the device using the biometric information acquisition device 509, and determines whether the face of the user U is detected in the photographed image (step S501). The boarding gate device 50 waits until the face of the user U is detected in the image by the biometric information acquisition device 509 (step S501, NO).

[0105] When the boarding gate device 50 determines that the face of user U has been detected by the biometric information acquisition device 509 (step S501, YES), it photographs the face of user U and acquires the facial image of user U as a target facial image (step S502).

[0106] Next, the boarding gate device 50 transmits the target face image of user U captured by the biometric information acquisition device 509 together with a matching request to the management server 10 via the network NW (step S503). As a result, the boarding gate device 50 requests the management server 10 to perform a 1:N matching of the target face image of user U captured by the biometric information acquisition device 509 with multiple registered face images registered in the user information DB 11 of the management server 10.

[0107] When the management server 10 receives the target face image and the matching request from the boarding gate device 50, it matches the face image of the user U (step S504). That is, the management server 10 matches the target face image received from the boarding gate device 50 with a plurality of registered face images registered in the user information DB 11 in a 1:N ratio.

[0108] If the management server 10 determines that the matching result is a mismatch (step S505, NO), the management server 10 transmits the matching result information to the boarding gate device 50 (step S507), and the process proceeds to step S509. On the other hand, if the management server 10 determines that the matching result is a match (step S505, YES), the process proceeds to step S506.

[0109] In step S506, the management server 10 acquires the user ID from the user information DB 11 based on the matching registered face image, and also acquires, using the user ID as a key, the credibility information from the credibility information DB 13. Then, the management server 10 transmits the acquired user ID and credibility information together with the matching result information to the boarding gate device 50 (step S508).

[0110] Next, if the boarding gate device 50 determines that the verification result is a match (step S509, YES), it determines whether the trustworthiness is equal to or greater than a predetermined threshold (step S510). If the boarding gate device 50 determines that the trustworthiness is equal to or greater than the predetermined threshold (step S510, YES), it opens the gate 511 (step S511). On the other hand, if the boarding gate device 50 determines that the trustworthiness does not meet the predetermined threshold (step S510, NO), it notifies the passenger of error information (step S515). For example, a notification screen including a message such as "Please check in at a manned counter" is displayed on the display device 507.

[0111] Next, the boarding gate device 50 transmits status information indicating that the boarding procedure for the user U has been completed after the facial image verification and the authentication result to the management server 10 via the network NW (step S512).

[0112] When the management server 10 receives the status information and authentication result from the boarding gate device 50, it updates the user information DB11 and the travel / authentication history information DB12 (step S513). Specifically, it updates the status in the user information DB11 to "boarding procedure completed: 4" using the user ID as a key. It also updates the authentication result for authentication stage ST4 of user U in the travel / authentication history information DB12 using the user ID as a key.

[0113] On the other hand, if the boarding gate device 50 determines that the matching result in the management server 10 is a mismatch (step S509, NO), the boarding gate device 50 notifies the user U that identity verification has failed (step S514). For example, the boarding gate device 50 displays a notification screen on the display device 507 notifying the user U that identity verification has failed.

[0114] [Immigration Inspection Procedures] 17 is a sequence diagram showing the operation of the automated gate device 60 and the management server 10. This process is executed when a user U who has arrived in a second country undergoes immigration inspection procedures.

[0115] The automated gate device 60 constantly or periodically photographs the area in front of the device using the biometric information acquisition device 609, and determines whether the face of the user U is detected in the photographed image (step S601). The automated gate device 60 waits until the face of the user U is detected in the image by the biometric information acquisition device 609 (step S601, NO).

[0116] When the automated gate device 60 determines that the face of user U has been detected by the biometric information acquisition device 609 (step S601, YES), it photographs the face of user U and acquires the facial image of user U as a target facial image (step S602).

[0117] Next, the automated gate device 60 transmits the target face image of user U captured by the biometric information acquisition device 609 together with a matching request to the management server 10 via the network NW (step S603). As a result, the automated gate device 60 requests the management server 10 to perform a 1:N matching of the target face image of user U captured by the biometric information acquisition device 609 with multiple registered face images registered in the user information DB 11 of the management server 10.

[0118] When the management server 10 receives the target face image and the matching request from the automated gate device 60, it matches the face image of the user U (step S604). That is, the management server 10 matches the target face image received from the automated gate device 60 with a plurality of registered face images registered in the user information DB 11 in a 1:N ratio.

[0119] If the management server 10 determines that the matching result is a mismatch (step S605, NO), the management server 10 transmits the matching result information to the automated gate device 60 (step S607), and the process proceeds to step S609. On the other hand, if the management server 10 determines that the matching result is a match (step S605, YES), the process proceeds to step S606.

[0120] In step S606, the management server 10 acquires the user ID from the user information DB 11 based on the matching registered face image, and acquires the credibility information using the user ID as a key from the credibility information DB 13. Then, the management server 10 transmits the acquired user ID and credibility information together with the matching result information to the automated gate device 60 (step S608).

[0121] Next, if the automated gate device 60 determines that the matching result is a match (step S609, YES), it determines whether the trustworthiness is equal to or greater than a predetermined threshold (step S610). If the automated gate device 60 determines that the trustworthiness is equal to or greater than the predetermined threshold (step S610, YES), it opens the gate 611 (step S611). On the other hand, if the automated gate device 60 determines that the trustworthiness does not meet the predetermined threshold (step S610, NO), it notifies the user of error information (step S615). For example, a notification screen including a message such as "Please complete immigration inspection procedures at a manned counter" is displayed on the display device 607.

[0122] Next, the automated gate device 60 transmits status information indicating that the immigration procedure for the user U has been completed after the facial image has been collated, and the authentication result to the management server 10 via the network NW (step S612).

[0123] When the management server 10 receives the status information and authentication result from the automated gate device 60, it updates the user information DB11 and the travel / authentication history information DB12 (step S613). Specifically, it updates the status in the user information DB11 to "Immigration inspection procedure completed: 5" using the user ID as a key. It also updates the authentication result for authentication stage ST5 of user U in the travel / authentication history information DB12 using the user ID as a key.

[0124] On the other hand, if the automated gate device 60 determines that the comparison result in the management server 10 is a mismatch (step S609, NO), the automated gate device 60 notifies the user U that identity verification has failed (step S614). For example, the automated gate device 60 displays a notification screen on the display device 607 notifying the user U that identity verification has failed.

[0125] [Customs Inspection Procedures] 18 is a sequence diagram showing the operation of the automated customs gate device 70 and the management server 10. This process is executed when a user U who has completed immigration procedures undergoes customs inspection procedures. Below, we will explain the process when user U is present in the gate passage between the entrance gate door 716 (entrance gate terminal 71) and the exit gate door 729 (exit gate terminal 72) of the automated customs gate device 70.

[0126] The automatic customs gate device 70 constantly or periodically photographs the gate passageway using the second camera 728, and determines whether the face of the user U is detected in the photographed image (step S701). The automatic customs gate device 70 waits until the face of the user U is detected in the image (step S701, NO).

[0127] When the automatic customs gate device 70 determines that the face of the user U has been detected in the image (step S701, YES), it photographs the face of the user U and acquires the facial image of the user U as a target facial image (step S702).

[0128] Next, the automated customs gate device 70 transmits the photographed target facial image of user U together with a matching request to the management server 10 via the network NW (step S703). As a result, the automated customs gate device 70 requests the management server 10 to match the photographed target facial image of user U with multiple registered facial images registered in the user information DB 11 of the management server 10 in a 1:N ratio.

[0129] When the management server 10 receives the target face image and the matching request from the automatic customs gate device 70, it matches the face image of the user U (step S704). That is, the management server 10 matches the target face image received from the automatic customs gate device 70 with a plurality of registered face images registered in the user information DB11 in a 1:N ratio.

[0130] If the management server 10 determines that the matching result is a mismatch (step S705, NO), the management server 10 transmits the matching result information to the automatic customs gate device 70 (step S707), and the process proceeds to step S709. On the other hand, if the management server 10 determines that the matching result is a match (step S705, YES), the process proceeds to step S706.

[0131] In step S706, the management server 10 acquires the user ID from the user information DB 11 based on the matching registered face image, and also acquires the creditworthiness information using the user ID as a key from the creditworthiness information DB 13. Then, the management server 10 transmits the acquired user ID and creditworthiness information together with the matching result information to the automatic customs gate device 70 (step S708).

[0132] Next, if the automatic customs gate device 70 determines that the comparison result is a match (step S709, YES), it determines whether the trustworthiness is equal to or greater than a predetermined threshold (step S710). If the automatic customs gate device 70 determines that the trustworthiness is equal to or greater than the predetermined threshold (step S710, YES), it executes customs inspection processing (step S711). Then, if there are no problems with the inspection, the automatic customs gate device 70 (exit gate terminal 72) opens the exit gate door 729 (step S712). On the other hand, if the automatic customs gate device 70 determines that the trustworthiness does not meet the predetermined threshold (step S710, NO), it notifies the user of error information (step S716). For example, a notification screen including a message such as "Please complete customs inspection procedures at a manned counter" is displayed on the display device 726. Then, the automatic customs gate device 70 (entrance gate terminal 71) opens the entrance gate door 716 (step S717).

[0133] Next, the automatic customs gate device 70 transmits status information indicating that the customs inspection procedure for the user U has been completed after the facial image verification and the authentication result to the management server 10 via the network NW (step S713).

[0134] When the management server 10 receives the status information and authentication result from the automatic customs gate device 70, it updates the user information DB11 and the travel / authentication history information DB12 (step S714). Specifically, it updates the status in the user information DB11 to "Customs inspection procedure completed: 6" using the user ID as a key. It also updates the authentication result for authentication stage ST6 of user U in the travel / authentication history information DB12 using the user ID as a key.

[0135] On the other hand, if the automatic customs gate device 70 determines that the comparison result in the management server 10 is a mismatch (step S709, NO), the automatic customs gate device 70 notifies the user U that identity verification has failed (step S715). For example, the automatic customs gate device 70 displays a notification screen on the display device 726 notifying the user U that identity verification has failed.

[0136] Next, a description will be given of the processing between the management server 10 and the business terminals 22, 32, 42, 52, 62, and 80. In the following, the business terminal 32 located at the security checkpoint (authentication stage ST2) will be described as a representative example.

[0137] FIG. 19 is a sequence diagram showing an example of processing between the management server 10 and the business terminal 32. As shown in FIG.

[0138] First, the business terminal 32 determines whether or not the passport of the user U has been held over the reading unit (not shown) of the medium reading device 228 (step S801), and waits until the passport is held over (step S801, NO).

[0139] Next, when the business terminal 32 determines that the passport has been held over the reading section of the medium reading device 228 (step S801, YES), it acquires the passport information of the user U from the passed passport (step S802).

[0140] Next, the business terminal 32 transmits the acquired passport information to the management server 10 (step S803). When the management server 10 receives the passport information from the business terminal 32, it acquires the user ID and creditworthiness information of user U using the passport number included in the passport information as a key (step S804). The management server 10 transmits the user ID and creditworthiness information of user U to the business terminal 32 (step S805).

[0141] Next, when the business terminal 32 receives the creditworthiness information of the user U from the management server 10, it displays notification information (screening criteria) corresponding to the creditworthiness of the user U contained in the creditworthiness information on the display device 227 (step S806).

[0142] 20 to 22 are diagrams showing examples of screens displayed by the business terminal 32. In Fig. 20, the screen displays information on the user U's credit rating rank ("Rank A (good traveler)"), information on the screening criteria to be applied to user U ("Please conduct the screening using the screening criteria for good traveler"), and guidance information regarding the next authentication stage ("Immigration screening procedures will be carried out in the priority lane numbered *. Please guide the user to the location where the procedure will be carried out.").

[0143] In Figure 21, the screen displays information on user U's credit rating ("Rank B (normal)"), information on the screening criteria to be applied to user U ("This is a first-time traveler. Please conduct screening using the normal screening criteria."), and guidance information regarding the next authentication stage ("Immigration screening procedures will be carried out in the general lane numbered *. Please guide the user to the location where they will be carried out.").

[0144] In Figure 22, the screen displays user U's credit rating rank information ("C rank (caution required)"), instructions on the screening criteria to be applied to user U ("This user has received a warning during security inspections in the past. Please conduct screening using stricter screening criteria than usual."), and guidance information regarding the next authentication stage ("Departure screening procedures will be carried out in the general lane numbered *. Please guide the user to the location where this will be carried out.").

[0145] Next, when the authentication process in the security inspection procedure (authentication stage ST2) is performed (step S807), the business terminal 32 transmits authentication result information and status information to the management server 10 (step S808).

[0146] Then, when the management server 10 receives the authentication result information and status information from the business terminal 32, it updates the status in the user information DB11 and updates the authentication result for the authentication stage ST2 in the travel / authentication history information DB12 (step S809), and terminates the processing.

[0147] As described above, according to the passenger control system 1 of this embodiment, when a user (passenger) U arrives at the airport and the passenger ID is identified at each authentication stage, personal attribute information, travel history information, and authentication history information of the user U can be obtained from the travel / authentication history DB 12. The credibility is calculated by applying history features from this history information to a predetermined algorithm. This allows the automated devices (automated gate devices, etc.) located at each authentication stage to control the continuation of the screening process at their own devices based on the credibility of the user U obtained from the management server 10.

[0148] Furthermore, notification information according to the trustworthiness is displayed on the screen of the business terminals located at each authentication stage. Therefore, by referring to the information on the screen, the person in charge at the authentication stage can conduct an examination in accordance with the examination criteria according to the trustworthiness of the user U. Specifically, for a user U with a high trustworthiness (a good traveler), a quick examination can be carried out under conditions that are more relaxed than usual. On the other hand, for a user U with a low trustworthiness, a more accurate examination can be carried out under conditions that are more strict than usual. As a result, the throughput throughout the entire airport can be improved.

[0149] [Second embodiment] The passenger control system according to the second embodiment will be described below. Note that the same reference numerals as those in the drawings of the first embodiment indicate the same objects. Explanations of the parts common to the first embodiment will be omitted, and differences will be described in detail.

[0150] In the first embodiment described above, the management server 10 calculates the creditworthiness of the user U from the history feature amount based on a predetermined algorithm. In contrast, the present embodiment differs from the first embodiment in that the management server 10 acquires the creditworthiness of the user U by applying the history feature amount of the user U who is refraining from traveling to a pre-trained learning model. In the present embodiment, the CPU 101 of the management server 10 also functions as a learning unit.

[0151] As an example of a learning method in the management server 10, learning can be performed using a general-purpose deep learning framework such as TensorFlow, Caffe2, or PyTorch.

[0152] 23 is a flowchart showing an example of processing by the management server 10 in this embodiment. This processing can be scheduled periodically, such as once a month. It may also be performed irregularly while the system is in operation.

[0153] First, the management server 10 acquires travel and authentication history data from the travel and authentication history DB 12 (step S901), and digitizes the information included in the travel and authentication history data (step S902).

[0154] Next, the management server 10 vectorizes the digitized information to acquire history feature amounts (step S903), inputs the history feature amounts to a neural network, and outputs the credibility (step S904).

[0155] Next, the management server 10 determines whether the error between the output credibility and a value based on predetermined training data is equal to or less than a threshold (step S905). If it is determined that the error is equal to or less than the threshold (step S905, YES), the learned learning model is saved in a storage area (step S907) and the process ends. On the other hand, if it is determined that the error exceeds the threshold (step S905, NO), the weighting between nodes in the neural network is updated (step S906), and the process returns to step S904.

[0156] FIG. 24 is a schematic diagram illustrating a neural network used in the learning process in this embodiment. The neural network shown in FIG. 24 includes an input layer having multiple nodes, a hidden layer having multiple nodes, and an output layer having one node. Each element of the history feature, which is an input value, is input to each node in the input layer. Each node in the hidden layer is connected to each node in the input layer. Each element of the input value input to the node in the hidden layer is used for calculation in each node in the hidden layer. Each node in the hidden layer calculates a calculated value using, for example, the input value input from each node in the input layer, a predetermined weighting coefficient, and a predetermined bias value. Each node in the hidden layer is connected to the output layer and outputs the calculated calculated value to a node in the output layer. The node in the output layer receives the calculated value from each node in the hidden layer.

[0157] The nodes in the output layer calculate the user's creditworthiness (estimated value) T using the calculated values ​​input from each node in the intermediate layer, the weighting coefficients, and the bias values. When training a neural network, for example, the backpropagation method is used. Specifically, the output value when data is input to the input layer is compared with the output value obtained from the training data, and the error resulting from the comparison is fed back to the intermediate layer. This is repeated until the error falls below a predetermined threshold. Through this training process, when any historical feature is input to the neural network (learning model), it is possible to output a creditworthiness with high accuracy.

[0158] 25 is a flowchart showing an example of processing by the management server 10 in the second embodiment. This processing is executed at a predetermined interval or when the examination for the second travel of the user U starts.

[0159] First, the management server 10 acquires travel and authentication history data (travel history information, authentication history information, and person attribute information) from the travel and authentication history information DB 12 for each passenger ID (step S1001).

[0160] Next, the management server 10 digitizes each of the travel history information, authentication history information, and personal attribute information included in the travel and authentication history data (step S1002).

[0161] Next, the management server 10 acquires history feature amounts expressed as vectors from the data obtained by digitizing the travel history information, authentication history information, and personal attribute information (step S1003).

[0162] Next, the management server 10 calculates the credibility of the user U by inputting the history feature into the trained learning model (step S1004).

[0163] Then, the management server 10 associates the calculated credit rating with the user ID and registers it in the credit rating information DB 13 (step S1005).

[0164] According to this embodiment, the management server 10 can output the credibility of the user U by inputting the historical feature amount of the user U into a trained learning model, which has the advantage of improving the processing speed.

[0165] [Third embodiment] The passenger control system 3 in this embodiment will be described below. Note that the same reference numerals as those in the first embodiment indicate the same objects. Explanations of the parts common to the first embodiment will be omitted, and differences will be described in detail.

[0166] FIG. 26 is a schematic diagram showing an example of the overall configuration of the passenger control system 3 in this embodiment. This embodiment differs from the above-described embodiments in that guidance information regarding screening is notified to a user terminal 90 carried or possessed by a user U (passenger) according to the user U's credit rating. The user terminal 90 is, for example, a tablet terminal, a smartphone, a mobile phone, etc. Furthermore, the terminal identification information of the user terminal 90 is assumed to be associated in advance with a passenger ID in, for example, the user information DB11.

[0167] 27 is a block diagram showing an example of the hardware configuration of the user terminal 90 in this embodiment. As shown in the figure, the user terminal 90 has a CPU 901, RAM 902, a storage device 903, an input device 906, a display device 907, and a wireless communication unit 908. Each device is connected to a bus line 905. The wireless communication unit 908 is a wireless communication interface based on standards such as Wi-Fi (registered trademark) and 4G, and is a module for communicating with the check-in terminal 20, etc.

[0168] FIG. 28 is a sequence diagram showing an example of processing by the management server 10 and the user terminal 90 in this embodiment.

[0169] First, the user terminal 90 transmits terminal identification information to the management server 10 (step S1101). When the management server 10 receives the terminal information from the user terminal 90, it acquires the user ID from the user information DB 11 using the terminal identification information as a key, and acquires the creditworthiness information of the user U from the creditworthiness information DB 13 (step S1102).

[0170] Next, the management server 10 creates guidance information regarding the examination for the user U based on the acquired credit rating (step S1103), and transmits the information to the user terminal 90 (step S1104).

[0171] Then, when the user terminal 90 receives the examination guide information from the management server 10, it displays it on the display device 907 (step S1105).

[0172] 29 is a diagram showing an example of a screen displayed by the user terminal 90 in this embodiment. Here, the screen displays the status (completed / incomplete) of the authentication stages ST1 to ST4, which indicate the inspection in the departure country, and guidance information for guiding the user U to the location of each authentication stage. Also, it is shown that the authentication stage ST3 (immigration inspection procedure) will be carried out in a priority lane.

[0173] In this way, according to this embodiment, guidance information according to the user's credit rating can be notified to the user terminal 90. By referring to the examination guidance information displayed on the user terminal 90, the user U can know the examination location and the like in advance. As a result, the examination efficiency can be improved.

[0174] [Fourth embodiment] The passenger control system of this embodiment will be described below. Note that the same reference numerals as those in the drawings of the first embodiment indicate the same objects. Explanations of the parts common to the first embodiment will be omitted, and differences will be described in detail.

[0175] In this embodiment, a signage terminal 92 is installed at each authentication stage. The signage terminal 92 is a terminal device for guiding the user U to an examination location according to the user's credibility before the user U undergoes examination at the authentication stage.

[0176] FIG. 30 is a diagram showing an example of the placement of a signage terminal 92 in this embodiment. Here, the signage terminal 92 is shown installed between the automated gate device 40 and the manned counter in the passageway of the immigration inspection area (authentication stage ST3). When the signage terminal 92 identifies the user U through biometric matching from a captured image, it displays guidance information for the user U. For example, a user U with low credibility can be guided to a manned counter. Note that the signage terminal 92 is similarly installed in the passageway at other authentication stages as well.

[0177] 31 is a block diagram showing an example of the hardware configuration of a signage terminal 92 in this embodiment. The signage terminal 92 has a CPU 921, a RAM 922, a storage device 923, a communication I / F 924, an input device 926, a display device 927, and a biometric information acquisition device 929. Each device is connected to a bus line 925.

[0178] FIG. 32 is a sequence diagram showing an example of processing by management server 10 and signage terminal 92 in this embodiment.

[0179] The signage terminal 92 constantly or periodically captures an image of the area in front of the device using the biometric information acquisition device 929, and determines whether the face of user U is detected in the captured image (step S1201). The signage terminal 92 waits until the biometric information acquisition device 929 detects the face of user U in the image (step S1201, NO). If the signage terminal 92 determines that the face of user U has been detected by the biometric information acquisition device 929 (step S1201, YES), it captures an image of the face of user U and acquires the facial image of user U as a target facial image (step S1202).

[0180] Next, the signage terminal 92 transmits the target face image of user U captured by the biometric information acquisition device 929 together with a matching request to the management server 10 via the network NW (step S1203). As a result, the signage terminal 92 requests the management server 10 to perform a 1:N matching of the target face image of user U captured by the biometric information acquisition device 929 with multiple registered face images registered in the user information DB 11 of the management server 10.

[0181] When the management server 10 receives the target face image and the matching request from the signage terminal 92, it matches the face image of the user U (step S1204). That is, the management server 10 matches the target face image received from the signage terminal 92 with a plurality of registered face images registered in the user information DB 11 in a 1:N ratio.

[0182] The management server 10 acquires the user ID associated with the registered face image from the user information DB 11, and acquires the creditworthiness information of the user U from the creditworthiness information DB 13 (step S1205).

[0183] Next, the management server 10 creates guidance information for the user U based on the acquired credibility (step S1206) and transmits it to the signage terminal 92 (step S1207).

[0184] Then, upon receiving the guidance information from management server 10, signage terminal 92 displays it on display device 927 (step S1208).

[0185] Fig. 33 is a diagram showing an example of a screen displayed by the signage terminal 92 in this embodiment. Here, information about the aircraft that user U is boarding (flight number, departure time), the progress of user U's procedures (completed / incomplete), and information about the location of each procedure (authentication stage) are displayed. In the case of Fig. 33, user U has completed the security inspection procedure and is next required to undergo immigration inspection, but it is displayed that immigration inspection will be carried out in the priority lane.

[0186] According to this embodiment, guidance information according to the trustworthiness of the user U can be displayed on the signage terminal 92. The user U can efficiently move to the inspection location by referring to the signage terminal 92 on the way to an automated device or a manned counter. This can improve the efficiency of inspections within the airport.

[0187] [Fifth embodiment] 34 is a block diagram showing the functions of an information processing device 100 in this embodiment. The information processing device 100 includes a determination unit 100A that determines the creditworthiness of a passenger based on historical information related to the passenger's first trip, and an output unit 100B that outputs information related to the second trip based on the creditworthiness associated with the identification information of the passenger who is about to make a second trip. This embodiment can improve the efficiency of various screening procedures for travelers.

[0188] [Sixth embodiment] 35 is a block diagram showing the functions of the terminal device 200 in this embodiment. The terminal device 200 includes an acquisition unit 200A that acquires a passenger's credit rating based on historical information about the passenger's first trip, and an output unit 200B that outputs information about the second trip based on the credit rating associated with the identification information of the passenger who is about to make a second trip. This embodiment can improve the efficiency of various screening procedures for travelers.

[0189] [Modified embodiment] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that would be understood by those skilled in the art can be made to the configuration and details of the present invention without departing from the gist of the present invention. For example, it should be understood that embodiments in which part of the configuration of one embodiment is added to or replaced with part of the configuration of another embodiment are also embodiments to which the present invention can be applied.

[0190] In the first embodiment described above, the management server 10 has a common database for multiple countries, and terminal devices installed at airports in each country access the database via the management server 10. However, the management server 10 may use only information obtained at an airport in one country. That is, the travel / authentication history information DB 12 and the like may be configured to store only authentication history information obtained at airports in Japan. In this case, for authentication stages ST1 (check-in procedure) to ST4 (boarding procedure) in Japan, the management server 10 may use the credibility calculated for each authentication stage from the authentication history information about the inspections (authentication stages ST1 to ST4) conducted when the user U previously departed from Japan. Similarly, when the user U enters Japan, the management server 10 may use the credibility calculated for each authentication stage from the authentication history information about the inspections (authentication stages ST5 to ST6) conducted when the user U previously entered Japan. In addition, if authentication history information exists for user U at the time of entry into and departure from Japan, the credibility of user U common across all authentication stages may be calculated from the authentication history information (at the time of entry and departure).

[0191] The scope of each embodiment also includes a processing method in which a program that operates the configuration of the embodiment to realize the functions of the above-described embodiment is recorded on a recording medium, the program recorded on the recording medium is read as code, and the program is executed on a computer. In other words, a computer-readable recording medium is also included in the scope of each embodiment. Furthermore, each embodiment includes not only a recording medium on which the above-described program is recorded, but also the program itself.

[0192] Examples of the recording medium that can be used include a floppy disk, a hard disk, an optical disk, a magneto-optical disk, a CD-ROM, a magnetic tape, a non-volatile memory card, etc. Furthermore, the scope of each embodiment is not limited to programs that execute processing by themselves recorded on the recording medium, but also includes programs that execute processing by operating on an OS in cooperation with other software or functions of an expansion board.

[0193] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes.

[0194] (Appendix 1) a determination unit that determines the creditworthiness of the passenger based on historical information related to the passenger's first journey; an output unit that outputs information about the second trip based on the credit rating associated with the identification information of the passenger who is about to make a second trip; An information processing device comprising:

[0195] (Appendix 2) the determination unit determines the creditworthiness based on a plurality of items included in the history information. 10. The information processing device according to claim 1.

[0196] (Appendix 3) the determination unit calculates the credibility based on an average of the history feature values ​​quantified for each of the items. 3. The information processing device according to claim 2.

[0197] (Appendix 4) the determination unit determines the creditworthiness based on a weighted average of the history feature values ​​quantified for each of the items. 4. The information processing device according to claim 3.

[0198] (Appendix 5) the determination unit determines the credibility for each of a plurality of items included in the history information. 10. The information processing device according to claim 1.

[0199] (Appendix 6) the determination unit calculates the trustworthiness based on a learning model that has previously learned a relationship between the history feature value quantified for each item and the trustworthiness. 3. The information processing device according to claim 2.

[0200] (Appendix 7) a learning unit that learns the learning model by updating weights between nodes of a neural network that outputs the confidence level for the input history feature; 7. The information processing device according to claim 6, further comprising:

[0201] (Appendix 8) The learning unit updates the learning model at a predetermined cycle. 8. The information processing device according to claim 7.

[0202] (Appendix 9) the learning unit updates the learning model in accordance with updates to the history information. 8. The information processing device according to claim 7.

[0203] (Appendix 10) The items include the results of the inspection conducted in connection with the first trip, 10. An information processing device according to any one of Supplementary Notes 2 to 9.

[0204] (Appendix 11) The review results are defined in three or more stages. 11. The information processing device according to claim 10.

[0205] (Appendix 12) The items include at least one of the departure point, arrival point, flight number of the aircraft used, departure date, and arrival date of the first trip. 12. An information processing device according to any one of Supplementary Notes 2 to 11. Processing equipment.

[0206] (Appendix 13) The items include at least one of the passenger's nationality, gender, and age. 12. An information processing device according to any one of Supplementary Notes 2 to 11.

[0207] (Appendix 14) The information regarding the second trip indicates criteria for screening to be conducted for the second trip, and the criteria for screening are determined according to the credit rating. 14. An information processing device according to any one of appendices 1 to 13.

[0208] (Appendix 15) The information regarding the second trip represents the criteria for a series of multiple screenings to be conducted during the second trip, and the criteria for each screening are determined according to the credit rating common to the multiple screenings. 15. The information processing device according to claim 14.

[0209] (Appendix 16) The information regarding the second trip indicates the criteria for a series of multiple screenings to be conducted during the second trip, and the criteria for each screening are determined according to the creditworthiness of each screening. 15. The information processing device according to claim 14.

[0210] (Appendix 17) The criteria for the examination are determined by comparing the credit score with a predetermined threshold. 17. An information processing device according to any one of appendices 14 to 16.

[0211] (Appendix 18) The criteria for the review are defined in multiple stages. 18. An information processing device according to any one of appendices 14 to 17.

[0212] (Appendix 19) The threshold varies depending on the type of examination. 18. The information processing device according to claim 17.

[0213] (Appendix 20) The information regarding the second journey is information that guides the passenger to a location corresponding to the inspection to be conducted during the second journey. 14. An information processing device according to any one of appendices 1 to 13.

[0214] (Appendix 21) an acquisition unit that acquires the creditworthiness of the passenger based on history information related to the passenger's first trip; an output unit that outputs information about the second trip based on the credit rating associated with the identification information of the passenger who is about to make a second trip; A terminal device comprising:

[0215] (Appendix 22) determining a creditworthiness of the passenger based on historical information relating to the passenger's first journey; outputting information about the second trip based on the creditworthiness associated with the identity of the passenger about to take the second trip; An information processing method comprising:

[0216] (Appendix 23) On the computer, determining a creditworthiness of the passenger based on historical information relating to the passenger's first journey; outputting information about the second trip based on the creditworthiness associated with the identity of the passenger about to take the second trip; A recording medium on which a program for executing the above is recorded. [Explanation of symbols]

[0217] NW...Network DA... Departure airport AA···Arrival Airport 1,3 Passenger Control System 10. Management Server 11...User information DB 12. Travel and authentication history information database 13...Credit information DB 20. Check-in terminal 22, 32, 42, 52, 62, 80... Business terminal 30. Security inspection device 40,60...Automated gate device 50. Boarding gate equipment 70 Automatic customs gate device 71 Entrance gate terminal 72 Exit gate terminal 90 User terminal 92 Signage terminal

Claims

1. a determining means for determining creditworthiness information for a passenger intending to make a new trip based on historical information relating to the passenger's past trips at multiple authentication stages; an output means for outputting information relating to the credit; An information processing device comprising:

2. determining information relating to the creditworthiness of a passenger intending to make a new trip based on historical information relating to the passenger's past trips at multiple authentication stages; outputting information about the trust; An information processing method comprising:

3. On the computer, determining information relating to the creditworthiness of a passenger intending to make a new trip based on historical information relating to the passenger's past trips at multiple authentication stages; outputting information about the trust; A program that executes the following.

4. a determination unit that determines, for a first passenger having first information including a history of past travel at a plurality of authentication stages, first screening criteria for travel screening in accordance with the first information, and determines, for a second passenger having second information including a history of past travel at a plurality of authentication stages, second screening criteria for travel screening in accordance with the second information; an output unit that outputs the second screening criteria, which are different from the first screening criteria, to a screening person who performs the screening; An information processing device comprising:

5. determining, for a first passenger having first information including a history of past travel at a plurality of authentication stages, first screening criteria for travel screening in accordance with the first information, and determining, for a second passenger having second information including a history of past travel at a plurality of authentication stages, second screening criteria for travel screening in accordance with the second information; outputting the second screening criteria, which are different from the first screening criteria, to a screening officer who performs the screening; An information processing method comprising:

6. On the computer, determining, for a first passenger having first information including a history of past travel at a plurality of authentication stages, first screening criteria for travel screening in accordance with the first information, and determining, for a second passenger having second information including a history of past travel at a plurality of authentication stages, second screening criteria for travel screening in accordance with the second information; outputting the second screening criteria, which are different from the first screening criteria, to a screening officer who performs the screening; A program that executes the following.

7. a determination unit that determines information about the creditworthiness of a passenger planning a new trip based on historical information about the passenger's past trips at multiple authentication stages; an output unit that outputs the examination criteria determined according to the credit information to an examiner who performs the examination; An information processing system comprising:

8. determining information relating to the creditworthiness of a passenger intending to make a new trip based on historical information relating to the passenger's past trips at multiple authentication stages; a step of outputting the examination criteria determined according to the credit information to an examiner who performs the examination; An information processing method comprising:

9. On the computer, determining information relating to the creditworthiness of a passenger intending to make a new trip based on historical information relating to the passenger's past trips at multiple authentication stages; a step of outputting the examination criteria determined according to the credit information to an examiner who performs the examination; A program that executes the following.

Citation Information

Patent Citations

  • Immigration examination system

    JP2013020316A

  • Immigration examination system and method

    JP2015222459A